Configuring Allowed List of Target URLs

Redirection, which is required by many applications and services, inherently brings in a security risk. Redirects are dangerous because unsuspecting users who are visiting trusted sites can be redirected to malicious sites that exploit the users' trust. A new featured, called allowed list, has been added that restricts target URLs to specific domains.

You can restrict target URLs to URLs which match the domains in the allowed list.

Any target URLs that use a domain that is not in the list are blocked and the user receives the following error message:

The request to provide authentication to a service provider has failed (outsidedomain.com-89F57BF823DFE551).

  1. On the Home page, click Applications > Select a Cluster > [application name] > SAML v2.0 Service Provider > Intersite Transfer.

  2. In Domain List, click Plus icon.

  3. Specify the domain name.

    The domain name must be a full domain name, such as www.example.com. Wildcard domain names, such as www.example.*.com, do not work.

  4. To edit an existing domain name, click the name, modify the name, and click OK.

  5. To delete an existing domain name, select the domain, and click Delete.

  6. Click OK.

  7. Update Identity Server.